Last updated: .
Who is responsible
OdoTrace is operated by Martynas Urbanavicius, established in Poland. You can reach it at [email protected]. The operator decides how the data described in this notice is handled, and is who to contact about it.
The short version
- You do not need an account, and no page asks for your name, email address or payment details.
- To run a check, OdoTrace sends the VIN you enter (and, if you add one, a number plate) to the official data sources listed below.
- The database keeps lookup results under a one-way digest (hash) of the VIN or plate rather than the identifier itself, and reuses them for a short time. The VIN and plate do appear in the web addresses of the lookups, so they can also appear in server and proxy logs (see below).
- OdoTrace shows vehicle facts only. It does not show who owns or has owned a vehicle.
- Analytics are self-hosted and cookieless. OdoTrace sets no cookies, and no third-party advertising or tracking scripts are loaded.
What you submit
- A VIN (vehicle identification number). Every vehicle check starts with it.
- Optional context. You can choose a purpose (buying, importing or owning) and a country. These choices decide which optional lookups and links the page offers. They are kept in the page address in your browser and are not themselves sent to a data source.
- Optional number plates. A Dutch plate if you add it for the RDW check, a UK plate if you use the separate UK plate lookup, and an Israeli or Slovenian plate if you use those lookups. The Slovenian lookup also needs the type and number of the registration certificate; the form clears that number from the page as soon as the request is made, and OdoTrace does not store it.
- Browser details that every web request carries, such as your IP address and browser type. See “Server and proxy logs” and “Analytics”.
The address of a report page contains the VIN (for example /precheck/?vin=…) and, for Dutch and UK lookups, the plate. That keeps a report reloadable, but it also means the identifier is in your browser history and in any link you copy. Anyone you share that link with will see the VIN.
A VIN can be personal data in some situations, for example when it can be linked to a particular person. OdoTrace therefore treats VINs and plates with care, as described here, even though it does not know who is entering them.
Where your lookup is sent
OdoTrace is a go-between. When you run a check, your browser calls OdoTrace’s own API (api.odotrace.com), which queries the sources below and returns a combined result. VIN decoding itself runs on OdoTrace’s server against its own copy of the data and does not send the VIN to a third party. Some sources are outside the EU/EEA, such as those in the UK, the United States and Israel.
| Source | Receives | When |
|---|---|---|
| UK DVSA MOT history | VIN | Automatically with each check. |
| Czech Ministry of Transport vehicle register | VIN | Automatically with each check, when that connection is available. |
| New York State DMV open inspection data | VIN | Automatically with each check while that source is switched on, which is the default. |
| Netherlands RDW open data | Dutch plate | Only when you add a Dutch plate. |
| UK DVSA MOT history, plate lookup | UK plate | Only when you use the separate UK plate lookup. |
| Danish inspection-report service (Færdselsstyrelsen) | VIN | Only when you ask for the Danish check, while that pilot is switched on. |
| Danish MotorAPI, and the Norwegian road authority’s vehicle register (Statens vegvesen) when switched on | VIN | Automatically, only after the usual checks have returned nothing for that VIN. Limited to one attempt per vehicle every five minutes. |
| Israel Ministry of Transport open data | Israeli plate | Only when you submit that lookup. |
| Slovenian eUprava public vehicle register | Plate, certificate type and certificate number | Only when you submit that lookup. |
| US NHTSA recalls, and for US context NHTSA crash-test ratings and US EPA fueleconomy.gov | Make, model and model year only (no VIN) | After a decode, and for US context. |
Other records, such as Czech inspection archive data, EU and German recall registers and mileage bands, are held in OdoTrace’s own database and queried locally. The methodology page lists every source with its licence. Each source publisher has its own rules for the requests it receives.
What OdoTrace stores and for how long
Durations below are the defaults in the application. The operator can change them in server configuration.
| What | Form | How long |
|---|---|---|
| Decoded vehicle patterns | Keyed by VIN positions 1–8, 10 and 11 (plus 12–14 for low-volume manufacturers), holding only pattern-level vehicle attributes. Not the full VIN and not the serial part. | Kept as a shared lookup cache with no expiry. |
| Source results for a vehicle | A SHA-256 digest of the VIN (or of the plate, or of VIN and plate together, depending on the source), with the dated records the source returned: dates, odometer readings, test outcomes and basic vehicle facts. The VIN or plate itself is not stored here. | Reused for 7 days. Older entries are never served and are replaced when that vehicle is looked up again; expired entries can also be purged. |
| Recall and US-market lookups | Make, model and year with the source’s model-level data. No VIN. | Reused for 7 days. |
| Partner link clicks | Partner name, time, and a SHA-256 digest of the VIN if one was in the link. See “Partner links”. | Deleted after 90 days by a daily clean-up job. |
A digest is not anonymous. Anyone who already knows a VIN or plate can compute the same digest, so OdoTrace treats digests as pseudonymous data and keeps them short-lived where it can.
Not stored: Israeli and Slovenian lookup inputs and results, Danish MotorAPI requests and responses, and Slovenian certificate details. For rate limiting, OdoTrace’s API counts requests per IP address in server memory over one-minute windows (by default 30 decode, 15 recall, 10 history and 30 partner-link requests per minute per address). These counters are not written to the database and are cleared when the service restarts. The protection against repeating the fallback lookup keeps a keyed digest of the VIN in server memory only; each entry expires after five minutes.
OdoTrace does not store owner or personal details about the people behind a vehicle. Where a register such as the Czech one reports owner or operator information, only counts are used, never identities. The site has no sign-up, newsletter or comment form, so it does not collect email addresses or names except in messages you send to [email protected].
Server and proxy logs
Traffic reaches OdoTrace through Cloudflare, which acts as a proxy and sees the requests and IP addresses passing through it under its own terms. The web server and the API also write ordinary access logs on the hosting server. Because lookups put the VIN (and, for some lookups, the plate) in the web address, these logs can contain them, along with your IP address, the time and your browser type. The homepage form also sends the VIN to the site as part of the address.
OdoTrace uses logs to run the service, investigate errors and abuse, and understand traffic, including bot and crawler traffic. They are not used for advertising. Server and proxy logs are kept for at most 30 days: a daily job deletes older entries, and logs are also cleared when the service is redeployed. The same 30-day limit applies to the copy of web-server request lines kept for traffic analysis. If you want a particular entry looked into, use the contact page.
Analytics
OdoTrace measures visits with Umami, which OdoTrace hosts itself at stats.odotrace.com. Your data is not passed to an outside analytics company.
- Umami uses no cookies. To count visits it works from a hash of technical details with a rotating secret value, and does not store your IP address.
- For ordinary page views it records the page path (the part after
?is left out), the page that referred you, the language, screen size, browser, operating system, device type and approximate location derived from your IP address. - On the vehicle check page it records a small number of coarse events: that a check started or finished, which source or stage answered and whether it found records, a time-range bucket, whether you used the example VIN, and the interface language and the country you picked as context. These events are labelled with a generic page name and address and no referrer. They never include the VIN, a plate or the report address.
- The tracker respects your browser’s “Do Not Track” setting: when it is on, no page views or events are sent.
Cookies and browser storage
OdoTrace’s pages and scripts set no cookies and use no local storage. There is one narrow use of session storage: if you arrive through a link carrying a campaign label that OdoTrace recognises (the ot_campaign address parameter with one of a few fixed values), the label is kept for that browser tab and added to analytics events so OdoTrace can tell which campaign a visit came from. It holds no VIN or personal data and is cleared when the tab closes or you arrive by another route. Cloudflare may set its own technical or security cookies depending on its configuration; OdoTrace does not control or read them.
Fonts are served from OdoTrace itself. The tax calculators run in your browser and do not send what you enter to a server.
Partner links and links to other sites
The report links to official registries and some third-party decoders. Opening them takes you to another site with its own privacy practices. Some links to decoder sites carry the VIN so that the destination is pre-filled; the VIN reaches that site only if you click. OdoTrace sets its pages to send no referrer to other sites.
If you choose a buying or importing purpose, the report can show a section about paid history reports with links to carVertical and autoDNA, labelled as affiliate links. These links go through api.odotrace.com/go/…, which records the partner name, the time and a SHA-256 digest of the VIN, then redirects you to the partner. The redirect does not add the VIN to the partner’s address. The partner’s own privacy policy applies from then on. See how OdoTrace is funded.
Your rights and how to ask
Depending on where you live, data protection law may give you rights to access personal data held about you, to have it corrected or deleted, to restrict or object to its use, and to complain to your local data protection authority. To ask about your data, email [email protected]; the contact page says what to include.
Because the database stores digests rather than VINs, OdoTrace can only find a stored record if you tell it the VIN or plate it was made from, and it would use that only to compute the digest and look. Records returned by a source belong to that source; to change them, contact the authority that publishes them.
Changes to this notice
This notice describes how the site works on the date shown at the top. If the site starts handling data differently, for example by adding a new source, a form or a different analytics tool, this page will be updated.